Skip to content
Request a demoView the portfolio

Legal

Data Processing Addendum

Version 1.0. Effective: August 19, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Trunnion AI, LLC ("Trunnion AI") and the customer identified in that agreement ("Customer") when the agreement references this DPA or when Trunnion AI processes personal data on Customer's behalf through a contracted Trunnion product ("Agreement"). It reflects the parties' intent that Customer acts as the controller (or a processor acting on behalf of a controller) and Trunnion AI acts as a processor of Customer personal data.

1. Scope and purpose limitation

Trunnion AI processes Customer personal data only to provide, secure, and support the contracted services, only on Customer's documented instructions (including the Agreement, configuration choices, and use of the services), and not for any other purpose. Trunnion AI does not sell Customer personal data, does not share it for cross-context behavioral advertising, and does not use Customer tenant data, prompts, uploaded content, or generated outputs to train or fine-tune any artificial intelligence model, whether its own or a third party's, unless the Agreement expressly provides otherwise. If Trunnion AI cannot follow an instruction because a law requires otherwise, it will inform Customer unless the law prohibits that notice.

2. Confidentiality

Trunnion AI ensures that every person it authorizes to process Customer personal data is bound by a written or statutory duty of confidentiality and processes that data only as needed to perform their role.

3. Security measures

Trunnion AI implements and maintains administrative, technical, and organizational measures appropriate to the risk of the processing, including encryption of personal data in transit, access controls scoped to role and need, logging of processing systems, tested backup and recovery procedures, and secure development practices with dependency, static-analysis, and secret scanning in the release pipeline. Deployment-specific measures, including on-premise and air-gapped configurations, are documented per engagement.

4. Subprocessors

Customer provides general authorization for the subprocessors listed at trunnion.ai/legal/subprocessors or in the deployment-specific documentation. Trunnion AI will provide at least 30 days' notice before adding or replacing a subprocessor that processes Customer personal data, except for an emergency replacement made to protect security or availability, which will be notified as soon as practicable. Customer may object on reasonable data protection grounds within the notice period; if the objection cannot be resolved, Customer may terminate the affected service and receive a pro rata refund of prepaid fees. Trunnion AI remains responsible for its subprocessors' performance and imposes data protection obligations on them that are no less protective than this DPA.

5. Assistance with data subject requests

Taking into account the nature of the processing, Trunnion AI provides reasonable assistance so Customer can respond to requests to exercise data subject rights (access, correction, deletion, portability, restriction, objection, and opt-out). If a data subject contacts Trunnion AI directly about Customer personal data, Trunnion AI will redirect the request to Customer rather than answer it, unless a law requires otherwise.

6. Personal data breach

Trunnion AI notifies Customer without undue delay, and in any case within 72 hours of confirming a personal data breach affecting Customer personal data. The notice describes the nature of the breach, the categories and approximate volume of data and data subjects affected so far as known, the likely consequences, the measures taken or proposed, and a contact point, and is supplemented as the investigation develops. Trunnion AI does not characterize an incident on Customer's behalf or notify Customer's regulators or data subjects unless the Agreement or a law requires it.

7. International transfers

Trunnion AI processes Customer personal data in the locations documented for the deployment. Where a cross-border transfer requires a lawful transfer mechanism, the parties will execute the applicable mechanism, such as standard contractual clauses, which are incorporated by reference where required.

8. Audits and information

Trunnion AI makes available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party assessments as they become available, security documentation, and responses to reasonable written security questionnaires no more than once per year, and allows audits required by law under reasonable confidentiality, scope, and scheduling terms.

9. Return and deletion

On termination or expiry of the Agreement, Trunnion AI returns Customer personal data in a commonly used format on request and then deletes it, or deletes it directly at Customer's choice, within the period stated in the Agreement and no later than 90 days after termination, except for copies a law requires Trunnion AI to retain and residual copies in encrypted backups, which expire on the documented backup schedule and are not restored to production except for disaster recovery, with deletion re-applied on any restore.

10. Order of precedence and contact

If this DPA conflicts with the Agreement, this DPA controls for the processing of personal data. Questions and legal notices about this DPA go to contact@viceroynm.com or by mail to Trunnion AI, LLC, 8100 Wyoming Blvd NE, Ste M4-301, Albuquerque, NM 87113, United States. See also the Privacy Notice and subprocessor list.

Necessary technology is always active because it provides security and remembers this choice.